One of the things I say all the time on this show is that rising tides raise all ships. I have been doing this a long time, and every bit of it, every hard lesson, every project that went sideways, every "oh, that is how that works" moment, came from somebody else being willing to share what they knew.
So this page is that. It is the list I would give you if we were sitting across a table and you asked me, "Aaron, who should I be paying attention to?"
These are not rankings. Nobody paid to be here. Some of these folks have been on the show, some have not yet. What they all have in common is that they put real work into the community and they give a lot of it away for free. If you are new to OT, start at the top of any section and just start reading. If you have been doing this twenty years, you will still find somebody here who makes you rethink something.
And if I missed somebody, and I definitely did, tell me and I will add them. This page is a living thing.
The People
Practitioners, researchers, and teachers who consistently give the good stuff away.
Mike Holcomb
If you have spent any time searching for how to get into OT cybersecurity, you have already found Mike. He is the on-ramp for this entire field. Twenty-plus years in IT security before Stuxnet pulled him into operational technology, then years as Fellow of Cybersecurity and ICS/OT Global Lead at Fluor, one of the biggest engineering and construction firms in the world, securing power plants, rail, refineries, and manufacturing. He now runs UtilSec independently, doing risk and maturity assessments and OT pentesting. MS in Information Security Engineering from SANS Technology Institute, plus CISSP, GRID, GICSP, GCIP, GPEN, GCIH, and 62443 certs.
Here is what makes Mike different: he gives almost all of it away. Forty-plus hours of free structured course content on YouTube. Two free e-books. Thirty-plus free infographics. TryHackMe rooms. A weekly newsletter. He also founded BSidesICS/OT, the community conference that runs alongside S4, plus BSides Greenville and the Upstate SC ISSA chapter. He picked up the SANS Difference Maker Award in 2025 for ICS/OT Defender of the Year and the BEER-ISAC Community Builder Award in 2026. If you know one person in this field, know Mike.
Ep 34: ICS/OT Cybersecurity: Events, Networking, and Industry Discussions with Mike Holcomb
Pascal Ackerman
Pascal is the deep end of the pool, and I mean that as a compliment. Dutch-born, master's in electrical engineering, started his career as a control engineer for an OEM, hands on industrial networks and automation before he ever touched security. Twenty-five-plus years across industrial network design, risk assessments, penetration testing, threat hunting, and forensics. That engineering-first background is exactly why his work lands with plant people instead of bouncing off them.
He is best known for Industrial Cybersecurity from Packt. The second edition runs 800 pages and is, as far as I am concerned, the closest thing our field has to a build-it-yourself manual for OT monitoring and threat hunting: IDMZ design, passive and active monitoring, threat intel, incident response, with lab exercises and companion code. Pascal is not a high-volume poster. No newsletter, no YouTube channel, no daily hot takes. He publishes rarely and densely. Follow him for depth, not cadence, and buy the book.
Clint Bodungen
Clint has been doing this for thirty years and has managed to reinvent what he does about three times without ever leaving OT. Air Force veteran. Research roles at Symantec, Booz Allen, and Kaspersky Lab, where he was Senior Researcher for Critical Infrastructure Threat Analysis. Lead author of Hacking Exposed: Industrial Control Systems, which is still one of the canonical offensive-security texts for ICS. He also built the Industrial Vulnerability Scoring System, an ICS-specific risk methodology.
What he is really known for, though, is gamification. ThreatGEN Red vs. Blue was the first online multiplayer game built to teach real cybersecurity, and AutoTableTop uses generative AI to build and run industry-specific incident response tabletops. Since 2024 his center of gravity has shifted hard into applied AI. He wrote the ChatGPT for Cybersecurity Cookbook, presented Project DARWIN (AI agent swarms mapping attack routes, genetic algorithms evolving defensive strategy) at the ICS Cybersecurity Conference, and in 2026 launched the open-source MindStone Agent work. He is one of very few people who can credibly stand in both the ICS field-experience camp and the AI engineering camp, and he ships open tooling instead of just opinions.

Oren Niskin
Oren came up the way I respect most, hands on the equipment first. Electrician's Mate (Nuclear) in the U.S. Navy aboard the USS Harry S. Truman. Then years as a rig electrician and IACS specialist on offshore drilling rigs with Diamond Offshore. Then consulting, first at EY and now at GuidePoint. When Oren talks about what it actually takes to patch something in a live plant, he is not theorizing.
His signature work is pragmatic vulnerability management in environments where downtime is genuinely dangerous. He has presented on cutting OT vulnerability management workload by roughly 80 percent through strategic prioritization: patch the critical diagnostic machine, leave the safety-critical process equipment alone, and be able to defend why. The other thing he has built is the open-source Packets-or-it-didn't-happen PLC Trainer Kit: nine chapters walking you through assembling real PLC hardware and field wiring, writing ladder logic, running Modbus TCP, building an HMI in Ignition, and then attacking the whole thing on actual hardware instead of a simulator. MIT licensed, free, and one of the best hands-on learning artifacts anybody has put out. He is also loud in the right way about hands-on experience beating credentials-first career building, and about earning trust with operations instead of throwing findings over the wall.

Josh Varghese
Josh is the guy for the networking layer that sits underneath everything else in OT security, the plumbing most of us wave at and move past. He founded Traceroute LLC in 2017 specifically because he saw the industrial market getting underserved on real networking depth. Before that he spent nearly a decade as technical lead at Industrial Networking Solutions building out their technical support and application engineering department, and before that he was an instrumentation and control specialist at Camp Dresser & McKee designing SCADA systems for municipal water utilities. BSEE from UT, plus a stack of networking certs.
Read his blog and you will see what I mean. Multi-part deep dives on how to actually pick a managed switch. NAT in industrial networks. Cellular in OT. PoE proprietary features. NAC reimagined for OT. OT network mapping. It is unglamorous, specific, and enormously useful, and it is the corrective a lot of OT defenders need when they keep running into problems that turn out to be network design problems wearing a security costume. He also runs #TracerouteCon for industrial networking professionals and delivers OT networking training. His LinkedIn is packet captures and troubleshooting walkthroughs, not thought leadership.

Patrick Gillespie
Patrick's origin story is my favorite kind. He spent eleven years in manufacturing, then found himself in a room where somebody asked if anyone knew industrial control systems. Nobody answered. He spoke up, not to volunteer for anything, just because he had actually done the work. That turned into building out an entire nationwide OT practice at GuidePoint, where he now runs a team of OT engineers.
That path is why he is worth listening to. He is not somebody who read about plant floors, he worked on them, and he came into security from the operations side rather than the other direction. He is good on the practical realities of bridging IT and OT inside real organizations: how the two groups actually talk to each other, where the handoffs break, and what it takes to build a services practice that plant people will let in the door. Based in Arkansas, and refreshingly plainspoken about all of it.
Andrew Ginter
Andrew is the most rigorous thinker I know on the question of what actually makes industrial security different from IT security. His argument, which he has been making consistently for years, is that safety-critical and reliability-critical systems deserve engineering-grade protection rather than probabilistic risk management borrowed from the enterprise. In IT you accept residual risk and buy insurance. You cannot insure your way out of a turbine coming apart or a chlorine release. That distinction sounds academic until you try to apply an IT risk framework to a plant and watch it fall over.
He has written several books on it, including Engineering-Grade OT Security: A Manager's Guide, Secure Operations Technology, and 21 Steps to Improve Cyber Security of SCADA Networks. He also co-hosts the Industrial Security Podcast with Nate Nelson, and the back catalog is a genuinely deep archive of conversations with practitioners across the field. Yes, he works for a vendor with a strong point of view about unidirectional gateways, and he is upfront about that. Read him anyway. The thinking stands on its own even where you land somewhere different on the technology.
Robert M. Lee
Rob is a vendor CEO, and I am putting him on this list anyway, because the body of work is real and a lot of it predates the company. Former US Air Force cyber warfare operations officer with time at the NSA. He led or co-led the analysis of the two most consequential ICS attacks we have public detail on: CRASHOVERRIDE, the malware behind the 2016 Ukraine grid attack, and TRISIS, the first malware built specifically to attack a safety instrumented system. That second one matters enormously, because it was the moment this field had to admit an adversary was willing to go after the layer that keeps people alive.
He also authored and teaches SANS ICS515, co-chairs the SANS ICS Security Summit, and co-authored the Five ICS Cybersecurity Critical Controls work with Tim Conway, which has probably done more to give small teams a defensible starting point than anything else published in the last decade. He is opinionated and he will argue with you in public. Take the free material, take the threat research, and make up your own mind about the rest.

Tom VanNorman
Tom is the reason a lot of people in this field have ever touched a real PLC. He co-founded ICS Village and he is hands-on with the gear that shows up on those conference floors, the OT Wall, the trainer kits, the capture-the-flag setups. Nearly three decades in operational technology, with deep expertise in building cyber-physical test environments for OT systems. He also retired from the Air National Guard after more than twenty years in cyber warfare operations. He is not a security person who wandered into industrial. He came up on the equipment.
What I appreciate about Tom is that he does the unglamorous work. Building and hauling hardware, standing at a table explaining Modbus to somebody for the ninth time that day, and doing it as a volunteer effort rather than a marketing play. If you meet him at a village, ask him how the kits get built. That conversation will teach you more about industrial protocols than most conference talks.
Derek Harp
Derek has spent his career building the rooms the rest of us stand around in. He founded (CS)²AI, the Control System Cyber Security Association International, and turned it into one of the few genuinely free front doors into this field. Weekly webinars, sector-specific online symposia, and the Level Zero Conference, most of it open to anybody who shows up. Before that he was an entrepreneur and community builder across the ICS security world, including founding NexDefense and helping stand up early ICS programs at SANS.
What I appreciate is that he built infrastructure for other people's voices instead of just his own. If you are early in your career, or your employer will not fund travel, Derek's work is probably the single most accessible on-ramp that exists. Start with a (CS)²AI webinar and you will run into half the names on this page eventually.
Marty Edwards
Marty is one of the most recognizable names in industrial cybersecurity, and the reason is range. He ran ICS-CERT at the Department of Homeland Security, which meant he was on point for US government coordination when industrial incidents happened. He later served as Managing Director of ISA, the standards body behind 62443. Before any of that he came up in industrial automation. Government, standards, and the plant floor is a rare combination, and it means he can talk to a regulator and a controls engineer in the same afternoon without losing either one.
He is a steady, non-hype voice on where policy and practice actually meet, and he has spent years pushing for industrial security to be treated as a public safety matter rather than an IT budget line. He also serves on the Building Cyber Security advisory board alongside me, so I have seen how he works up close.
Dale Peterson
Dale is the closest thing OT security has to an editorial page, and I mean that as high praise. He founded Digital Bond, one of the first ICS security research shops, then built S4 into the most technically ambitious conference in the field. But the reason to follow him is not the conference. It is that he is one of a very small number of senior people who will publicly criticize vendors, government programs, consolidation deals, and lazy consensus thinking with his own name attached.
He is also the field's leading contrarian on prioritization, pushing consequence-first thinking, questioning whether detection-heavy programs earn their keep, and arguing that asset owners over-invest in visibility and under-invest in recovery. You will not agree with everything Dale says. That is the point. His Friday newsletter is a curated read of the week's ICS news with a paragraph of opinion attached to each item, and it is one of the highest-signal things in my inbox.
Dr. Sarah Fluchs
Sarah is who you follow if you want OT security explained as an engineering discipline instead of an IT discipline. Her recurring argument, that automation engineers already have the mental models security needs, and that security requirements should be replaced by engineered outcomes, is genuinely different from the standard "get visibility, then segment" story we all tell. She writes with diagrams and worked examples, and she is refreshingly willing to say out loud when a popular framework is over-complicated.
She is also the single best English-language source on EU regulation actually landing on industrial vendors and operators: the Cyber Resilience Act, NIS2, the Machinery Regulation, and how they interact. If you have got European suppliers or European sites, and most of us do, this is a blind spot worth closing. She sits on the EU Commission's Cyber Resilience Act Expert Group and co-convenes 62443-3-2, so she is writing from inside the process, not about it. Her S4 recap posts are some of the best conference synthesis anybody writes.
Dean Parsons
Dean sits right at the intersection of practitioner and educator, and he fills a gap almost nobody else does: content written for the leader, not the engineer. He co-authored and teaches SANS ICS418, ICS Security Essentials for Leaders, and instructs ICS515. Most OT material is aimed at engineers or SOC analysts. Very little is aimed at the plant manager or the director who has to fund the program and answer to a board. That is Dean's lane.
He is also unusually generous with free, immediately usable stuff: tabletop exercise planning cheat sheets, a Five ICS Critical Controls assessment cheat sheet, an OT advisory overview, all downloadable without a sales call. His 2026 position has been that generic tabletop exercises are close to worthless and organizations should be running targeted drills mapped to the Five ICS Critical Controls. That is a concrete, arguable thesis, which is more than most awareness content manages. He runs his own independent shop out of Newfoundland.
Chris Sistrunk, PE
Chris is a rare one: a researcher who was an asset owner first. Years as a transmission and distribution engineer at Entergy before he ever went to Mandiant, and it shows in how he talks. Substations, relays, and DNP3, not abstractions. He co-created the Robus DNP3 fuzzing research that surfaced a large batch of real ICS vulnerabilities, and that work is still one of the most consequential pieces of independent ICS protocol research anybody has done. Licensed PE.
He is equally valuable as a connector. He has been a fixture in the ICS Village and DEF CON ICS scene, organized BSidesJackson, and is one of those people who consistently amplifies other researchers' work instead of his own. Despite the vendor employer, his feeds are research, advisories, and community events, not product. If you are on the grid or utility side and want a bridge into the broader hacker research community, follow Chris.
Organizations & Communities
Groups doing the unglamorous work of training people and moving the field forward.

ICS Village
If you have never put your hands on a real PLC, ICS Village is how that changes. They are a volunteer-run nonprofit, forty-plus volunteers including instructors, SOC operators, plant engineers, and policy advisors, who haul live industrial gear onto conference floors so people can actually touch and break the equipment they are expected to defend. The OT Wall, the portable OT Trainer Kits, capture-the-flag competitions, and 200- and 300-level workshops. They report 5,000-plus participants across 31-plus events.
What makes them unusual is that they run two tracks that almost never coexist. On the practitioner side, they travel. DEF CON, DEF CON Singapore, DEF CON Middle East, S4, RSAC, and regional BSides events. Wherever the industry gathers, there is a good chance the OT Wall is set up in a corner of it. On the policy side, they run Critical Effect (formerly Hack the Capitol) in DC, which puts ICS practitioners in the same room as CISA leadership, national labs, and think tanks. They are simultaneously the entry ramp into this field, the free hands-on lab, and the channel through which practitioner reality reaches policymakers. Co-founded by Bryson Bort and Tom VanNorman. PrOTect IT All is a proud sponsor.
Building Cyber Security
Building Cyber Security covers a niche almost nobody else does, and it is one I care about enough to sit on their advisory board: the cyber-physical risk inside buildings themselves. HVAC, access control, elevators, lighting, life safety, and the whole proptech layer bolted on top of it. We spend a lot of time in this industry talking about plants and substations, and then we walk into an office tower or a hospital or a data center where the building management system is wide open and nobody actually owns it.
BCS is a private-sector nonprofit that brings asset stakeholders, technology firms, and insurers together to fix that. The framework is rooted in ISA/IEC 62443 and CIS standards, and the model runs on four pillars: build the cyber-physical framework, assess infrastructure and issue cyber performance ratings, deliver education and certification, and maintain ongoing preparedness so a rating still means something six months later. The part I find most compelling is the theory of change. BCS deliberately ties the framework to insurance, lending, and ratings agencies, betting that market pressure moves faster than regulation ever will. If your scope touches buildings, campuses, data centers, healthcare real estate, or REIT portfolios, this is the group doing the work to make building automation security a rated, insurable, certifiable thing instead of a footnote. Led by Lucian Niemeyer, with an advisory board that includes Admiral Mike Rogers, Marty Edwards, and a deep bench of commercial real estate CIOs. Full disclosure: I am on that advisory board.

SANS ICS
SANS ICS is the center of gravity for OT security practitioners in North America, and the free tier is genuinely substantial. The ICS/OT workforce posters, the Five Critical Controls material, the summit presentation archive, and recorded webcasts are all no-cost and get used as reference material inside real programs. Curriculum led by SANS Fellow Tim Conway; the ICS Security Summit is co-chaired by Conway and Robert M. Lee.
The reason to treat this as a follow and not just a training vendor: the summit talks and posters are where a big share of our shared vocabulary originates. When the whole field suddenly starts saying the same phrase, it usually started here.
ISA Global Cybersecurity Alliance
If your audience is asset owners, 62443 is the standard you get audited against, that shows up in procurement contracts, and that insurers ask about. ISAGCA is where the free, plain-language explanation of it lives. It is a multi-stakeholder forum under ISA spanning asset owners, vendors, integrators, and government agencies. This is deliberately an organization rather than a person. 62443 is a committee product, and the useful output is the guides and quick-start materials, not any single author's opinion. Following ISAGCA is how you see 62443 work products before they turn into procurement requirements.

(CS)²AI
The best value-per-dollar on this entire page, because the dollar amount is zero. (CS)²AI runs a weekly online webinar series plus recurring sector-specific online symposia, oil and gas, manufacturing, and others, all free to attend. If you cannot get travel approved, or you are early in your career and paying out of pocket, start here. They also run the Level Zero Conference.
Conferences Worth Your Travel Budget
The honest one-line version of how these differ.
| Event | What it is really for |
|---|---|
| S4 | Where the field is going |
| SANS ICS Summit | Learn to actually do the job |
| GridSecCon | Electric sector coordination |
| ICS Cybersecurity Conference | The deepest practitioner bench |
| DEF CON ICS Village | Hands on real hardware |
| Critical Effect | Policy and regulation |
| BSidesICS/OT | Community and the on-ramp |
| RSTCON | Deep technical research and exploitation |
| OT.SEC.CON. | Regional Gulf Coast asset owners |
| Level Zero | National-lab-grade technical content |
Still to come in 2026
RSTCON
RSTCON exists because its founders got tired of watching conferences drift away from deep research. Jay and Matthew Miller started it to bring back what you used to get at an early DEF CON or an Infiltrate: cutting-edge research, exploitation, and real technical tradecraft aimed squarely at OT, ICS, critical infrastructure, and critical manufacturing. If the comparison helps, it is far more DEF CON than Black Hat.
The other thing they set out to do is get the money and the brains in the same room, vendors funding the work, the researchers doing it, and offensive security people who can poke holes in it, all brainstorming the same problems together. That combination is genuinely hard to find anywhere else. I did not start this one, I just support it, and I had the founders on the show to explain it in their own words.
- CostSee the 2026 site for current pricing.
- Heads upDetails are still being finalized. Follow them on LinkedIn or X and join the Discord for the latest.
- Best forResearchers, offensive security people, and practitioners who want the deep technical end rather than the strategy track.

ICS Cybersecurity Conference, 25th Anniversary
The longest-running industrial cybersecurity event there is, going since 2002, now run by SecurityWeek. Deliberately not a vendor expo. The agenda skews toward control engineers, incident retrospectives, and protection strategy across manufacturing, energy, utilities, chemicals, oil and gas, transportation, and water. This year is the 25-year anniversary edition, and note that it has moved from Atlanta to Nashville. If you have been before, update your mental map.
- Cost$2,195 standard (pre-reg through Oct 1), $2,395 onsite, $1,795 US government. Optional 3-day hands-on training add-on, $3,995, US citizens only.
- Best forAsset owners who want the deepest practitioner bench in the field.
GridSecCon 2026, "Unified Resilience"
North America's largest grid security conference, now in its 15th year. Co-hosted by NERC and the E-ISAC with a rotating regional entity, SERC hosts this year. Over 50 sessions from 100-plus industry and government experts, covering both cyber and physical security, which almost no other OT conference does. Heavy E-ISAC, DOE, FBI, and CISA participation. The vibe is utility practitioner and sector coordination, not hacker con.
- CostNot publicly posted, register through the organizer. Early bird closed July 12.
- Best forElectric utility asset owners, grid security leaders, physical security teams. Weak fit if you are in manufacturing or oil and gas.
- Heads upSome E-ISAC content is restricted to vetted electricity-sector participants. Check eligibility before you book travel.
Put these on your 2027 calendar

S4x27
The biggest and most ambitious ICS/OT security conference in the world, and the one that sets the agenda for everything else. New research, new vendor launches, and the arguments that shape the industry usually break here first. Dale Peterson curates hard for novelty over vendor pitches, so it is forward-looking rather than 101-level. S4x26 sold out at 1,100 tickets with 100-plus on the waitlist; the new venue holds 1,500. The hallway and evening track is genuinely half the value. ICS Village is usually there too, so you can get hands on real gear between sessions.
- CostTiered, $1,695 to $2,395 depending on how early you buy.
- TimingTickets go on sale September 15, 2026, and the lowest tier is only held for 36 hours. That is roughly $500 for showing up on time.
- Best forResearchers, consultants, senior practitioners, anyone who needs to know where this is heading. Not the best first OT conference.
BSidesICS/OT 2027
Mike Holcomb's community-run counterweight to S4, deliberately scheduled so that people flying in for S4 get a free-form practitioner day first. Classic BSides ethos: open CFP, no vendor keynotes, community speakers, accessible to people whose employer will not fund a $2,000 ticket. It is the friendliest room in OT security and the best place to meet people before the S4 firehose opens up.
- CostNot yet posted. BSides events are conventionally free or very low cost.
- Best forNewcomers, career changers, practitioners on a budget, and anybody already traveling to S4.

SANS ICS Security Summit & Training 2027
The training-anchored event of the ICS calendar: two to three days of practitioner talks bolted onto a week of the SANS ICS course catalog. Content is defense-oriented and immediately applicable rather than cutting-edge, vendor presence is light, and it feels like a classroom with a conference attached. The single best "I actually need to learn this" option on the list. Co-chaired by Tim Conway and Robert M. Lee.
- CostSummit only $975. Summit plus a course from $3,505. Individual courses $3,505 to $9,230.
- Budget tipSANS runs a volunteer program that lets you attend the two-day summit free in exchange for on-site help. Worth knowing if travel budget is your constraint.
OT.SEC.CON. 2027
A regional, practitioner-first OT security conference built to get Gulf Coast owner-operators in the same room as security people. It grew out of Houston's HOU.SEC.CON. community, so the vibe is approachable and hands-on, heavily petrochemical and energy flavored rather than academic. It is the least expensive and least intimidating event on this list, and the most likely to have people who actually run the plant sitting in the audience.
- CostNot publicly posted. Historically low hundreds for this family of events.
- Best forGulf Coast energy and process-industry asset owners without a national travel budget.
- NoteDo not confuse this with OTSEC Summit (Abu Dhabi) or OTsec World, different events entirely.

Critical Effect (formerly Hack the Capitol)
The policy event of the OT security world, presented by ICS Village with IST's UnDisruptable27 project and the law firm Akin. Built explicitly to put ICS practitioners in front of policymakers, think tanks, and media instead of in front of each other. The framing is national security and public safety, with human life as the stated stakes. If you want to understand where federal attention is heading, or influence it, this is the room. Note the name change: if you are searching for Hack the Capitol, this is it now.
- CostNot publicly posted. Early bird discounts, plus free tickets for students, military, and government.
- Best forLeaders, policy people, government and military, anyone in a regulatory or advocacy role.

DEF CON 35, ICS Village
The most hands-on OT experience anywhere. Real PLCs, HMIs, the OT Wall, the OT Trainer Kit fleet, and a Modbus Write Playground you can actually touch and break. Two parallel tracks, the Creator Stage for technical talks and the Village Stage for workshops (Mike Holcomb has taught intro OT/ICS sessions there). Pure hacker culture, zero vendor polish, and the cheapest way to get real hands on industrial gear. DEF CON is one of my favorite weeks of the year, and the ICS Village is where our people are. Budget your time accordingly.
- CostVillage access is free with a DEF CON badge. DC34 badges ran $560 to $600. DC35 pricing not out yet.
- Best forResearchers, red teamers, IT security people crossing into OT, hands-on learners, students.
- NoteICS Village participation in DC35 is expected but not yet formally announced.

ISA OT Cybersecurity Summit 2027
ISA's own industrial cybersecurity event, built around the 62443 standards ISA writes, which is exactly what makes it different. Aimed at OT cybersecurity people at management level and above across energy, manufacturing, water and wastewater, oil and gas, and maritime. Deliberately mid-sized; the 2026 Prague edition drew 314 attendees, 41 speakers, and 18 sponsors. It is a real travel commitment from the US, so weigh it against whether you have European operations or a 62443 compliance mandate.
- Cost2027 not published. 2026 ran €762 ISA member, €990 non-member for the full conference.

Level Zero Conference 2027
(CS)²AI's in-person flagship, with support from Georgia Tech and Idaho National Laboratory. Aimed at the people responsible for building, maintaining, and defending ICS/OT environments: engineers, executives, compliance managers, enterprise security teams. The INL and Georgia Tech backing gives it a national-lab and academic research flavor the commercial conferences do not have, in a smaller room.
- CostNot publicly posted.
DISTRIBUTECH International 2027
Not an OT security conference, and I will not pretend otherwise. It is the dominant North American utility T&D trade show: 18,000-plus attendees, 684 exhibitors, 800-plus utility attendees. Cybersecurity is one thread inside a very large grid modernization, metering, and DER event. The reason it is on this list is that it is where your utility peers already are. If you are going anyway, there is real security content to pick up.
- CostNot publicly posted. A Utility Partner Program typically discounts or comps utility staff.
RSAC Conference 2027
Included with a caveat: for most of my audience, this is not the trip. RSAC has OT and critical infrastructure sessions and a growing OT vendor presence, but there is no dedicated OT track deep enough to justify it for a plant-side asset owner. Go if your job includes vendor evaluation, budget ownership, or board-level reporting. If you do go, ICS Village is usually on the floor, and that is the corner of RSAC where you will find our people.
Free and Online, No Travel Required
That is the list. It is not complete and it never will be. This field moves, people change jobs, conferences move cities, and somebody new starts publishing something great every month.
If you are brand new: pick one person from the top section, one free resource, and one conference you could realistically get to. That is a year's worth of growth right there. If you have been around a while: find the person on this list you disagree with and go read them anyway. That is where the good stuff is.
And if I left somebody off, let me know. Rising tides raise all ships.